security: fix audit vulnerabilities (RUSTSEC-2026-0007, RUSTSEC-2021-0141)
- Update bytes 1.11.0 -> 1.11.1 (fixes integer overflow in BytesMut::reserve, CVE-2026-25541) - Replace unmaintained dotenv 0.15.0 with dotenvy 0.15.7 (RUSTSEC-2021-0141) - Note: rsa 0.9.10 (RUSTSEC-2023-0071) has no patch yet, pulled transitively via jsonwebtoken
This commit is contained in:
+2
-2
@@ -10,7 +10,7 @@ axum = { version = "0.8.8", features = ["multipart", "http1", "tokio", "macros"]
|
||||
tokio = { version = "1.49.0", features = ["full"] }
|
||||
tokio-util = { version = "0.7.18", features = ["io", "codec"] }
|
||||
tokio-stream = { version = "0.1.18", features = ["fs"] }
|
||||
bytes = "1.11.0"
|
||||
bytes = "1.11.1"
|
||||
tempfile = "3.25.0"
|
||||
tower = "0.5.3"
|
||||
tower-http = { version = "0.6.8", features = ["fs", "compression-gzip", "trace", "cors", "add-extension", "request-id"] }
|
||||
@@ -36,7 +36,7 @@ argon2 = "0.5.3"
|
||||
rand_core = { version = "0.6", features = ["std", "getrandom"] }
|
||||
hyper = { version = "1.8.1", features = ["full"] }
|
||||
quick-xml = "0.39.0"
|
||||
dotenv = "0.15.0"
|
||||
dotenvy = "0.15.7"
|
||||
lru = "0.16.3"
|
||||
memmap2 = "0.9"
|
||||
http-range-header = "0.4"
|
||||
|
||||
Reference in New Issue
Block a user